GDPR & Trust
This page is maintained by Launch Safe. It explains, in plain language, how we build and operate the platform in line with the UK GDPR and the Data Protection Act 2018. It is not a certification or a substitute for our full Privacy Policy.
Our approach
GDPR compliance is not a badge we buy — it is an ongoing way we design and operate the platform. Because Launch Safe handles names, contact details, resident communications, inspection records and contractor information, data protection is built into the product from the outset.
Data protection principles in practice
Lawful, fair, transparent
Clear notices about what we collect and why. No hidden processing, no third-party marketing, no data sales.
Data minimisation
We collect only what the platform needs to manage compliance — no unnecessary personal fields, no shadow profiles.
Access & rectification
Users can view and correct their profile data at any time. Organisation admins control access to building records.
Right to erasure
Account and personal data deletion is available on request from the Profile page or by emailing us.
Storage limitation
Personal data is retained only while your organisation has an active subscription plus a defined post-termination window for legal and audit obligations.
Integrity & confidentiality
Encryption in transit, role-based access, row-level security in the database, and least-privilege service credentials.
Controller and processor roles
Launch Safe acts as data controller for account information (the details used to create and manage a Launch Safe account) and as data processor for the compliance data uploaded by our customer organisations (buildings, inspections, actions, documents and related records). Customer organisations remain the controller of the compliance data they upload.
What we collect
- Account data — name, work email, organisation, role.
- Compliance data — building records, inspection notes, photos, documents, actions.
- Contact information — resident, contractor and stakeholder details entered by users.
- Technical data — browser, device, IP address and audit logs needed to operate the service securely.
Your rights
Depending on your location and role, you may exercise the following rights over your personal data:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion of your account and personal data.
- Restriction and objection — limit or object to certain processing.
- Portability — receive your data in a common, machine-readable format.
Signed-in users can export or request deletion of their profile data from the Profile page. All other requests can be sent to info@launchsafe.co.uk and are actioned within one calendar month.
Sub-processors
We use a small number of vetted providers to host the platform, store data, deliver email and run AI-assisted features. Each is bound by a data processing agreement requiring appropriate security and confidentiality. A current sub-processor list is available on request.
International transfers
Where personal data is transferred outside the UK or EEA, we rely on appropriate safeguards such as UK International Data Transfer Agreements or Standard Contractual Clauses with our sub-processors.
Breach response
We maintain an internal process to detect, contain and investigate personal data incidents. Where a reportable breach occurs, we will notify the ICO within 72 hours and inform affected customers without undue delay in line with UK GDPR Articles 33 and 34.
Contact
For any data protection questions, DPA requests or subject access requests, email info@launchsafe.co.uk. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.